<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81.20 JHF 89 SAML Forced Re-authentication in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232009#M44745</link>
    <description>&lt;P&gt;Im fairly positive there is a feature on Azure portal you need to enable to make this work. Let me talk to one of my coleagues, Im sure he will know what it is.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2024 14:48:17 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-11-07T14:48:17Z</dc:date>
    <item>
      <title>R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/231992#M44739</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Has anyone figured out how to enable this function: &lt;SPAN&gt;Identity Awareness(SAML):&amp;nbsp;&lt;/SPAN&gt;Forced Re-authentication, which requires mandatory login for each session?&lt;/P&gt;&lt;P&gt;Previously, I followed the instructions described in sk180948.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 13:15:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/231992#M44739</guid>
      <dc:creator>Alex2023</dc:creator>
      <dc:date>2024-11-07T13:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232009#M44745</link>
      <description>&lt;P&gt;Im fairly positive there is a feature on Azure portal you need to enable to make this work. Let me talk to one of my coleagues, Im sure he will know what it is.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 14:48:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232009#M44745</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-07T14:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232010#M44746</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/88621"&gt;@Alex2023&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe this is what you need to follow, but will verify.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/saas-apps/check-point-remote-access-vpn-tutorial" target="_blank"&gt;https://learn.microsoft.com/en-us/entra/identity/saas-apps/check-point-remote-access-vpn-tutorial&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 14:51:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232010#M44746</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-07T14:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232015#M44747</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;thank you for your message. I set up the Azure authorization according to that guide, and everything is working perfectly. However, I can’t find a function in Azure that would enforce authentication each time a client connects.&lt;/P&gt;&lt;P&gt;I used sk180948 to implement persistent authentication. I was hoping there might now be an option in Check Point to handle this without manually editing the config file.&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 15:12:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232015#M44747</guid>
      <dc:creator>Alex2023</dc:creator>
      <dc:date>2024-11-07T15:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232017#M44748</link>
      <description>&lt;P&gt;This option likely pertains to Conditional Access Policies in Office365. See more here: &lt;A href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-session-lifetime#require-reauthentication-every-time" target="_blank"&gt;https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-session-lifetime#require-reauthentication-every-time&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 15:26:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232017#M44748</guid>
      <dc:creator>Alex2023</dc:creator>
      <dc:date>2024-11-07T15:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232018#M44749</link>
      <description>&lt;P&gt;Yep, thats it!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 15:27:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232018#M44749</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-07T15:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232057#M44759</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Simply activating this function in the Conditional Policy didn’t change anything. The MS documentation includes the following: 'Sign-in frequency set to every time works best when the resource has the logic of when a client should get a new token.'&lt;/P&gt;&lt;P&gt;It seems to me that some configuration change might also be needed on the Check Point side. Is there anyone we could ask about this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 08:34:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232057#M44759</guid>
      <dc:creator>Alex2023</dc:creator>
      <dc:date>2024-11-08T08:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232094#M44769</link>
      <description>&lt;P&gt;Thats the same link my collegue sent me as well, sorry. Im not aware of anything else. Maybe you can double check with TAC or lets see if someone else may know.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 12:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232094#M44769</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-08T12:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232095#M44770</link>
      <description>&lt;P&gt;After a few hours, it started working better. Authentication is requested if the last session was more than 5 minutes ago.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 12:09:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232095#M44770</guid>
      <dc:creator>Alex2023</dc:creator>
      <dc:date>2024-11-08T12:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232096#M44771</link>
      <description>&lt;P&gt;Maybe just took some time...&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 12:10:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232096#M44771</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-08T12:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232097#M44772</link>
      <description>&lt;P&gt;Agreed, Microsoft always requires some time.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 12:12:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232097#M44772</guid>
      <dc:creator>Alex2023</dc:creator>
      <dc:date>2024-11-08T12:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232099#M44773</link>
      <description>&lt;P&gt;I wish that were only true for Microsoft lol&lt;/P&gt;
&lt;P&gt;Anyway, is it working for all users now?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 12:15:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232099#M44773</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-08T12:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232100#M44774</link>
      <description>&lt;P&gt;Yes, this works for everyone who falls under this Conditional Policy.&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 12:17:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232100#M44774</guid>
      <dc:creator>Alex2023</dc:creator>
      <dc:date>2024-11-08T12:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232139#M44794</link>
      <description>&lt;P&gt;I diffed the relevant file in R81.20 JHF 89 versus a fresh install of R81.20.&lt;BR /&gt;There is one line added to the file that didn't exist before:&lt;/P&gt;
&lt;P&gt;'ForceAuthn' =&amp;gt; ( ( IsForceAuthnOverride((string)$realm_name) || (property_exists($realm, "ForceAuthn") &amp;amp;&amp;amp; ($realm-&amp;gt;ForceAuthn === true))) ? true : false ),&lt;/P&gt;
&lt;P&gt;Not exactly sure where it is reading this property from, though.&lt;BR /&gt;I'll see if I can get more information.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 15:32:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/232139#M44794</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-08T15:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233564#M45201</link>
      <description>&lt;P&gt;It would be nice if there was at least an sk for those new SAML features (Request Signing, Assertion Decryption and&amp;nbsp;&lt;SPAN&gt;Forced Re-authentication).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;SAML for remote access vpn broke for us on upgrade to take89, and we ended up reverting and installing take84 instead.&lt;/P&gt;&lt;P&gt;We were assuming it was related to those new features, but struggled to find any information about them.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 15:19:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233564#M45201</guid>
      <dc:creator>Ben_Dunkley</dc:creator>
      <dc:date>2024-11-22T15:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233578#M45211</link>
      <description>&lt;P&gt;Yup, I see same thing on jumbo 90 as well, that exact line.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 20:14:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233578#M45211</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-22T20:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233579#M45212</link>
      <description>&lt;P&gt;I actually gave feedback for the sk, lets hope they made a modification.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 20:15:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233579#M45212</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-22T20:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233583#M45214</link>
      <description>&lt;P&gt;sk180948 is&amp;nbsp;where the existing "ForceAuthn = true" modification is documented.&lt;BR /&gt;I left feedback on this SK and it appears R&amp;amp;D plans to update this with the relevant information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 21:19:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233583#M45214</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-22T21:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233617#M45215</link>
      <description>&lt;P&gt;I got an email today about the sk being modified and when I checked it, it indeed was.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2024 21:04:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233617#M45215</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-24T21:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 JHF 89 SAML Forced Re-authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233680#M45226</link>
      <description>&lt;P&gt;It looks like an additional modification to the file needs to be made for R82 and R81.20 JHF 89 (If I'm understanding the SK correctly).&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 14:32:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-JHF-89-SAML-Forced-Re-authentication/m-p/233680#M45226</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-25T14:32:39Z</dc:date>
    </item>
  </channel>
</rss>

